Skip to content
-Legal

Privacy policy

How Precision collects, uses, discloses and protects personal data - on this website, and in the payroll platform.

Last updated: 17 September 2025

1. Introduction

Professional Passport Shield Ltd ("we", "us", "our") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, disclose and protect the personal data of:

We are registered in England and Wales under company number 16656701 and our registered office is at 8 The Manor, Shinfield, Reading, England, RG2 9DP.

This policy sets out the basis on which any personal data we process is handled. Please read it carefully.

2. Data controller and data processor

Understanding our role is crucial under UK data protection law:

  • For our client's employees: when we process employee data (for example names, salaries and bank details) to run payroll on our client's behalf, the client is the Data Controller. They determine the "why" and "how" of the processing. We are the Data Processor, acting on their documented instructions. This relationship is governed by our Data Processing Addendum (DPA), which forms part of our Terms and Conditions.
  • For our client data and website visitors: for the personal data of our clients (business contacts) and visitors to our website, we are the Data Controller.

3. Information we collect and how we use it

Data categoryWhat we collectLawful basis for processingPurpose of processing
Client employee data (processed as a processor)Name, address, date of birth, NI number, salary, bank details, tax code, pension contributions, leave, sickness.Necessary for the performance of a contract (between us and our client) and to comply with legal obligations (for example HMRC reporting).To calculate pay, deductions and taxes; to generate payslips; to submit RTI filings to HMRC; to administer pension contributions.
Client business data (controller)Business name, business address, client contact name, email, phone number, financial information for billing.Performance of a contract (to provide our services to you) and legitimate interests (for account management and service updates).To set up your account, provide customer support, invoice for services and manage our relationship.
Website visitor data (controller)IP address, browser type, device information, pages visited. See our Cookie Policy.Consent (for non-essential cookies) and legitimate interests (for essential website operation and security).To improve our website experience, analyse traffic, and ensure network and information security.
Marketing data (controller)Name, business email address, company name.Consent (for direct marketing emails) or legitimate interests (for sending relevant business-to-business marketing).To send you marketing communications about our services, events and industry news. You can opt out at any time.

The public marketing pages of this website are published as static files and set no cookies of their own. They do load web fonts from Google Fonts, which means your browser makes a request to a Google server and Google receives your IP address as part of that request. Standard web server logs are kept by our hosting provider for operational and security purposes.

4. How we share your personal data

We may share personal data with the following third parties:

  • HMRC: we are legally obliged to submit payroll data to HMRC under the Real Time Information (RTI) regime.
  • Pension providers: to facilitate auto-enrolment pension contributions, as instructed by you.
  • Sub-processors: we use trusted third-party service providers who help us deliver our services (for example cloud hosting providers, email communication services and support ticketing systems). These sub-processors are subject to strict data processing agreements and cannot use your data for their own purposes.
  • Professional advisers: such as accountants, lawyers and consultants where necessary.
  • Law enforcement or regulatory bodies: where we are required to do so by law.

We will never sell your personal data.

5. International transfers

We primarily store and process data within the UK and European Economic Area (EEA). If we ever need to transfer personal data outside the UK or EEA (for example if a sub-processor uses servers in the USA), we will ensure a valid transfer mechanism is in place as required by UK law, such as:

  • The UK International Data Transfer Agreement (IDTA) or Addendum.
  • Transfers to countries deemed by the UK to provide an adequate level of data protection.

6. Data security

We have implemented robust technical and organisational measures to protect your personal data from accidental loss, unauthorised access, use, alteration or disclosure. These include encryption, secure access controls and regular security testing. Further detail is set out on the security and trust page.

7. Data retention

  • Client employee data: we will retain this data only for as long as necessary to provide the payroll services and to fulfil our legal and regulatory obligations. HMRC requires payroll records to be kept for a minimum of three years from the end of the tax year they relate to, although six years or more is often recommended. On termination of our contract with a client, we will delete or return all data in accordance with our DPA and our data retention schedule.
  • Client data: we will retain this for as long as you have an account with us, and for a period afterwards to comply with legal obligations (for example financial records) and for legitimate business purposes (for example resolving disputes).

8. Your data protection rights

Under UK data protection law you have rights, including:

  • The right to access - you have the right to request copies of your personal data.
  • The right to rectification - you have the right to request correction of inaccurate information.
  • The right to erasure - you have the right to request that we erase your personal data, under certain conditions.
  • The right to restrict processing - you have the right to request the restriction of processing your personal data, under certain conditions.
  • The right to data portability - you have the right to request the transfer of your data to another organisation, or to you, under certain conditions.
  • The right to object to processing - you have the right to object to our processing of your personal data, under certain conditions.
  • Rights in relation to automated decision making and profiling.

How to exercise your rights

  • If you are a client or website visitor: please contact us using the details in section 10.
  • If you are an employee of a client: you should first contact your employer, who is the Data Controller. They are responsible for responding to your requests. We will support our clients as the Data Processor in fulfilling these obligations.

We will respond to any valid request within one month.

9. How to complain

If you have any concerns about our use of your personal data, please contact us first so we can try to resolve the issue.

You also have the right to make a complaint at any time to the Information Commissioner's Office (ICO), the UK regulator for data protection issues - www.ico.org.uk. We would, however, appreciate the chance to deal with your concerns before you approach the ICO.

10. Contact us

To exercise your rights, ask questions or raise concerns about this policy, contact our Data Protection Officer at:

11. Changes to this privacy policy

We may update this policy from time to time. The latest version will always be posted on our website. We will notify our clients of any material changes that affect how we process data.

-Book a demonstration

See what precise payroll control looks like.

Book a tailored demonstration using your payroll volumes, operating model and compliance priorities.